CVE-2026-92161 | FriendsOfFlarum OAuth up to 1.7.3/2.0.0-beta.3 Discord OAuth Provider provideTrustedEmail Verified improper authentication

SecurityVulns

A vulnerability classified as critical has been found in FriendsOfFlarum OAuth up to 1.7.3/2.0.0-beta.3. The affected element is the function provideTrustedEmail of the component Discord OAuth Provider. The manipulation of the argument Verified leads to improper authentication.

This vulnerability is traded as CVE-2026-92161. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More